Discovery Pipeline Architecture
Gaussian runs a lightweight local sensor thread on macOS that continuously audits AI asset posture without performance overhead:
Technical Architecture
Continuous discovery of AI clients, undeclared MCP tools, and shadow execution paths across macOS endpoints.
The Shadow AI Risk in Developer Environments
Shadow AI Discovery in Gaussian is an automated endpoint capability engine that identifies unapproved AI client executables, scans local Model Context Protocol (mcp.json) tool configs, and cross-references active posix_spawn binary calls against enterprise compliance policies on macOS.
Gaussian runs a lightweight local sensor thread on macOS that continuously audits AI asset posture without performance overhead:
Scans active process signatures and macOS app bundles across Cursor, Claude, Windsurf, Copilot, Zed, VS Code, JetBrains, and Gemini.
Identifies 35+ client families using ClientMetadata.swift signature definitions.
Parses local configuration files for declared MCP tools, extension manifests, and skill customization directories.
Monitors mcp.json, settings.json, SKILL.md, and skills.json inheritance graphs.
Correlates declared configs with real OS-level Endpoint Security (ES) process spawns and Network Extension (NE) egress flows.
Flags undeclared stdio tools, unapproved HTTP endpoints, and shadow AI runners instantly.
Assigns risk scores based on tool privileges, secret access, and network egress destinations.
Exports structured telemetry events to SIEM platforms (Splunk, Datadog) and enterprise dashboard.
Gaussian automatically inventories and governs 35+ AI client families, desktop applications, and CLI runners:
com.todesktop.230313mnuyzscwq~/Library/Application Support/Cursor/User/globalStorage/mcp.jsoncom.anthropic.claudedesktop~/Library/Application Support/Claude/claude_desktop_config.jsoncom.exafunction.windsurf~/.codeium/windsurf/mcp_config.jsondev.zed.Zed~/.config/zed/settings.jsoncom.microsoft.VSCode~/.config/Code/User/settings.jsoncom.anthropic.claudecode~/.claude/mcp.jsoncom.jetbrains.intellij~/Library/Application Support/JetBrains/IntelliJIdea2024.3/options/ai.xmlcom.google.antigravity~/.gemini/antigravity-ide/mcp/When an AI client spawns a process or opens a socket connection to a tool server not listed in approved enterprise policy, Gaussian classifies the event into a risk tier:
Shadow AI Discovery is the continuous automated identification of AI client applications (Cursor, Claude Desktop, Windsurf, Zed), MCP tool server manifests, and unapproved local AI runners across enterprise workstations.
Gaussian combines configuration file parsing (mcp.json, settings.json) with OS-level Endpoint Security (ES) process tracking to catch stdio tool spawns and HTTP socket connections in real time.
Running AI agents on Mac at scale? We'll tune policy with you.
Design partners →